ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A financial institution is evaluating its risk exposure to a potential cyberattack that could disrupt its online banking services. They have determined that such an attack has a 'Moderate' likelihood of occurring and would result in 'High' financial and reputational damage. The institution has a stated 'risk appetite' that it will not accept any risks with an inherent risk level greater than 'Medium'. What is the most appropriate risk treatment strategy for this identified risk?

  1. ATransfer the risk by purchasing cyber insurance.
  2. BAvoid the risk by discontinuing online banking services.
  3. CMitigate the risk by implementing stronger security controls.
  4. DAccept the risk, as it falls within the risk tolerance.
Show answer & explanation

Correct answer: C. Mitigate the risk by implementing stronger security controls.

The risk (Moderate likelihood, High impact) exceeds the organization's 'Medium' risk appetite. Since avoiding online banking isn't practical, and transferring might not cover all damages, the most common and appropriate treatment for an unacceptable risk of this nature is mitigation through stronger controls to reduce either the likelihood or the impact.

Why the other options are wrong

  • A. Transferring via insurance is a valid strategy, but mitigation is often the primary response for critical services and can reduce the cost of insurance.
  • B. Avoiding the risk by discontinuing a core service is usually impractical and not the 'most appropriate' initial treatment for an established service.
  • D. The risk is 'Moderate/High', which exceeds the 'Medium' risk appetite, so acceptance is not appropriate.

Risk Treatment

The process of selecting and implementing measures to modify risk.

  • Includes Avoid, Transfer, Mitigate, and Accept (ATMA).
  • Chosen based on risk assessment results and organizational risk appetite/tolerance.
  • Aims to bring residual risk to an acceptable level.

Memory trick: ATMA: Avoid, Transfer, Mitigate, Accept – always choose wisely!

More Security Principles questions